First published: Fri May 13 2016(Updated: )
Multiple vulnerabilities were fixed in moodle 3.0.4, 2.9.6, 2.8.12 and 2.7.14 releases. ============================================================================== MSA-16-0013: Users are able to change profile fields that were locked by the administrator Description: User editing form only disabled the profile fields in UI and did not actually prevent users from editing them Issue summary: Tricky users can change locked profile fields Severity/Risk: Minor Versions affected: 3.0 to 3.0.3, 2.9 to 2.9.5, 2.8 to 2.8.11, 2.7 to 2.7.13 and earlier unsupported versions Versions fixed: 3.0.4, 2.9.6, 2.8.12 and 2.7.14 Reported by: Vadim Dvorovenko Issue no.: MDL-53954 CVE identifier: <a href="https://access.redhat.com/security/cve/CVE-2016-3729">CVE-2016-3729</a> Changes (master): <a href="http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-53954">http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-53954</a> ============================================================================== MSA-16-0015: Information disclosure of hidden forum names and sub-names. Description: Name of the inaccessible forum or forum discussion could be disclosed as part of the error message on the subscription page Issue summary: Information disclosure of hidden forum names and sub-names. Severity/Risk: Minor Versions affected: 3.0 to 3.0.3, 2.9 to 2.9.5 and 2.8 to 2.8.11 Versions fixed: 3.0.4, 2.9.6 and 2.8.12 Reported by: Callum Issue no.: MDL-53696 CVE identifier: <a href="https://access.redhat.com/security/cve/CVE-2016-3731">CVE-2016-3731</a> Changes (master): <a href="http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-53696">http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-53696</a> ============================================================================== MSA-16-0016: User can view badges of other users without proper permissions Description: Capability check to view other badges was performed for the current user instead for the user whose badges are being viewed Issue summary: Badges code checks viewotherbadges capability in the wrong context Severity/Risk: Minor Versions affected: 3.0 to 3.0.3, 2.9 to 2.9.5, 2.8 to 2.8.11, 2.7 to 2.7.13 and earlier unsupported versions Versions fixed: 3.0.4, 2.9.6 and 2.8.12 Reported by: Tim Hunt Issue no.: MDL-53589 CVE identifier: <a href="https://access.redhat.com/security/cve/CVE-2016-3732">CVE-2016-3732</a> Changes (master): <a href="http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-53589">http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-53589</a> ============================================================================== MSA-16-0017: Course idnumber not protected from teacher restore Description: During the course restore teacher could overwrite idnumber even without having the capability to change it Issue summary: Course idnumber not protected from teacher restore Severity/Risk: Minor Versions affected: 3.0 to 3.0.3, 2.9 to 2.9.5, 2.8 to 2.8.11, 2.7 to 2.7.13 and earlier unsupported versions Versions fixed: 3.0.4, 2.9.6, 2.8.12 and 2.7.14 Reported by: Donna Hrynkiw Issue no.: MDL-51369 CVE identifier: <a href="https://access.redhat.com/security/cve/CVE-2016-3733">CVE-2016-3733</a> Changes (master): <a href="http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-51369">http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-51369</a> ============================================================================== MSA-16-0018: CSRF in script marking forum posts as read Description: CSRF possible in the URL that marks forum posts as read Issue summary: Forum markposts.php missing sesskey check Severity/Risk: Minor Versions affected: 3.0 to 3.0.3, 2.9 to 2.9.5, 2.8 to 2.8.11, 2.7 to 2.7.13 and earlier unsupported versions Versions fixed: 3.0.4, 2.9.6, 2.8.12 and 2.7.14 Reported by: Andrew Nicols Issue no.: MDL-53755 CVE identifier: <a href="https://access.redhat.com/security/cve/CVE-2016-3734">CVE-2016-3734</a> Changes (master): <a href="http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-53755">http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-53755</a> ==============================================================================
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle Moodle | =2.7.0 | |
Moodle Moodle | =2.7.0-beta | |
Moodle Moodle | =2.7.0-rc1 | |
Moodle Moodle | =2.7.0-rc2 | |
Moodle Moodle | =2.7.1 | |
Moodle Moodle | =2.7.2 | |
Moodle Moodle | =2.7.3 | |
Moodle Moodle | =2.7.4 | |
Moodle Moodle | =2.7.5 | |
Moodle Moodle | =2.7.6 | |
Moodle Moodle | =2.7.7 | |
Moodle Moodle | =2.7.8 | |
Moodle Moodle | =2.7.9 | |
Moodle Moodle | =2.7.10 | |
Moodle Moodle | =2.7.11 | |
Moodle Moodle | =2.7.12 | |
Moodle Moodle | =2.7.13 | |
Moodle Moodle | =2.8.0 | |
Moodle Moodle | =2.8.1 | |
Moodle Moodle | =2.8.2 | |
Moodle Moodle | =2.8.3 | |
Moodle Moodle | =2.8.4 | |
Moodle Moodle | =2.8.5 | |
Moodle Moodle | =2.8.6 | |
Moodle Moodle | =2.8.7 | |
Moodle Moodle | =2.8.8 | |
Moodle Moodle | =2.8.9 | |
Moodle Moodle | =2.8.10 | |
Moodle Moodle | =2.8.11 | |
Moodle Moodle | =2.9.0 | |
Moodle Moodle | =2.9.1 | |
Moodle Moodle | =2.9.2 | |
Moodle Moodle | =2.9.3 | |
Moodle Moodle | =2.9.4 | |
Moodle Moodle | =2.9.5 | |
Moodle Moodle | =3.0.0 | |
Moodle Moodle | =3.0.0-beta | |
Moodle Moodle | =3.0.0-rc1 | |
Moodle Moodle | =3.0.0-rc2 | |
Moodle Moodle | =3.0.0-rc3 | |
Moodle Moodle | =3.0.0-rc4 | |
Moodle Moodle | =3.0.1 | |
Moodle Moodle | =3.0.2 | |
Moodle Moodle | =3.0.3 | |
redhat/moodle | <3.0.4 | 3.0.4 |
redhat/moodle | <2.9.6 | 2.9.6 |
redhat/moodle | <2.8.12 | 2.8.12 |
redhat/moodle | <2.7.14 | 2.7.14 |
composer/moodle/moodle | >=2.7<2.7.14 | 2.7.14 |
composer/moodle/moodle | >=2.8<2.8.12 | 2.8.12 |
composer/moodle/moodle | >=2.9<2.9.6 | 2.9.6 |
composer/moodle/moodle | >=3.0<3.0.3 | 3.0.3 |
=2.7.0 | ||
=2.7.0-beta | ||
=2.7.0-rc1 | ||
=2.7.0-rc2 | ||
=2.7.1 | ||
=2.7.2 | ||
=2.7.3 | ||
=2.7.4 | ||
=2.7.5 | ||
=2.7.6 | ||
=2.7.7 | ||
=2.7.8 | ||
=2.7.9 | ||
=2.7.10 | ||
=2.7.11 | ||
=2.7.12 | ||
=2.7.13 | ||
=2.8.0 | ||
=2.8.1 | ||
=2.8.2 | ||
=2.8.3 | ||
=2.8.4 | ||
=2.8.5 | ||
=2.8.6 | ||
=2.8.7 | ||
=2.8.8 | ||
=2.8.9 | ||
=2.8.10 | ||
=2.8.11 | ||
=2.9.0 | ||
=2.9.1 | ||
=2.9.2 | ||
=2.9.3 | ||
=2.9.4 | ||
=2.9.5 | ||
=3.0.0 | ||
=3.0.0-beta | ||
=3.0.0-rc1 | ||
=3.0.0-rc2 | ||
=3.0.0-rc3 | ||
=3.0.0-rc4 | ||
=3.0.1 | ||
=3.0.2 | ||
=3.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.